CVE-2018-18025
- EPSS 0.21%
- Veröffentlicht 07.10.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:23
In ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the EncodeImage function of coders/pict.c, which allows attackers to cause a denial of service via a crafted SVG image file.
CVE-2018-18021
- EPSS 0.09%
- Veröffentlicht 07.10.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:23
arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles the KVM_SET_ON_REG ioctl. This is exploitable by attackers who can create virtual machines. An attacker can arbitrarily redirect the hypervisor flow of ...
CVE-2018-17456
- EPSS 66.23%
- Veröffentlicht 06.10.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:54:27
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has ...
CVE-2018-0503
- EPSS 0.38%
- Veröffentlicht 04.10.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:22
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where contrary to the documentation, $wgRateLimits entry for 'user' overrides that for 'newbie'.
CVE-2018-0504
- EPSS 1.61%
- Veröffentlicht 04.10.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:22
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains an information disclosure flaw in the Special:Redirect/logid
CVE-2018-0505
- EPSS 0.43%
- Veröffentlicht 04.10.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:22
Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock
CVE-2018-11784
- EPSS 85.12%
- Veröffentlicht 04.10.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:01
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause...
CVE-2018-17972
- EPSS 0.06%
- Veröffentlicht 03.10.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:18
An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11. It does not ensure that only root may inspect the kernel stack of an arbitrary task, allowing a local attacker to exploit racy stack unwindi...
CVE-2018-17540
- EPSS 3.98%
- Veröffentlicht 03.10.2018 20:29:09
- Zuletzt bearbeitet 21.11.2024 03:54:34
The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate.
CVE-2015-9267
- EPSS 0.04%
- Veröffentlicht 01.10.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 02:40:12
Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse pro...